Get practical hosting tips in your inbox

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Follow Us
Follow Us

Website security statistics - how many sites get hacked?

Mendy Perlman, Researcher at Web Hosting Services By: Mendy Perlman | Updated: July 15, 2026 | Fact Checked |
Cite this Research

Cite this research

APA

Perlman, M. (2026, July 15). Website security statistics: how many sites get hacked? Web Hosting Services. https://webhostingservices.co/research/website-hacking-statistics

MLA

Perlman, Mendy. “Website Security Statistics: How Many Sites Get Hacked?” Web Hosting Services, 15 July 2026, https://webhostingservices.co/research/website-hacking-statistics.

Chicago

Perlman, Mendy. “Website Security Statistics: How Many Sites Get Hacked?” Web Hosting Services. Last modified July 15, 2026. https://webhostingservices.co/research/website-hacking-statistics.

Research highlights: A data breach now costs $4.44 million globally on average and a record $10.22 million in the US, per IBM. Most breaches are not exotic: the human element factors into 62% of them, according to the 2026 Verizon DBIR. Google Safe Browsing protects over 5 billion devices and flags thousands of newly unsafe sites daily, many of them legitimate sites that were compromised.

Featured infographic showing two bars on a shared dollar axis, a $4.44 million global average breach cost and a $10.22 million US average, beside a card reading 62% of breaches involve the human element.
A breach costs $4.44 million on average worldwide and $10.22 million in the United States, and 62% of them involve a person.

How many websites are hacked each day?

Note: precise daily hack counts cannot be verified; the widely-cited “30,000 a day” figure is a dated estimate, not a confirmed measurement.

  • No source reliably counts every site compromised each day, so exact figures are guesses.
  • The often-repeated 30,000 sites per day stat traces to old estimates and is unverified.
  • Google says Safe Browsing discovers thousands of newly unsafe sites every day.
  • Many of those are legitimate sites that were compromised, not malicious from the start.
  • Many compromises involve known security gaps, outdated software or stolen credentials rather than brand-new attack techniques.

Metric

Status

“30,000 sites/day” figure

Dated, unverified

Newly unsafe sites found daily (Google)

Thousands

The honest answer is that the daily count is not publicly measurable from a single authoritative source. Rather than chase a viral round number, the useful takeaway is that Google keeps discovering thousands of newly unsafe sites each day, and many are legitimate websites compromised through known or preventable weaknesses.



What percentage of websites contain malware or vulnerabilities?

Note: these are scan-based estimates from Sucuri and reflect its SiteCheck and remediation datasets, not the entire web at scale.

  • Sucuri’s 2024 SiteCheck dataset found an overall website infection rate of 1.66% across 70.8 million remote scans.
  • It detected 1,176,701 infected websites, with 822,651 involving active malware infections or malicious redirects.
  • SEO spam was another major category, with 422,741 detections, showing that many compromises target traffic and rankings.
  • In Sucuri’s 2023 remediation dataset, 39.1% of CMS applications were outdated at the point of infection.
  • Sucuri also found 13.97% of compromised websites had at least one vulnerable plugin or theme at remediation.
  • These figures are methodology-dependent, since remote scan data and cleanup data measure different populations.

Metric

Figure

Sucuri SiteCheck infection rate (2024 scans)

1.66%

Infected websites detected by Sucuri SiteCheck (2024)

1,176,701

Active malware or redirect detections (2024)

822,651

SEO spam detections (2024)

422,741

Outdated CMS at point of infection (Sucuri 2023 remediation data)

39.1%

Compromised sites with vulnerable plugin/theme (Sucuri 2023 remediation data)

13.97%

The key distinction is infection versus exposure. Sucuri’s remote scanner found a low single-digit infection rate in its 2024 dataset, while its cleanup data shows that outdated CMS software and vulnerable third-party components remain common on already compromised websites.



What are the most common causes of website breaches?

  • The human element was present in 62% of breaches in the 2026 Verizon DBIR.
  • Exploiting software vulnerabilities became the most common initial access vector, at 31% of breaches in Verizon’s 2026 dataset.
  • Credential abuse fell to 13% as an initial access vector, while the full DBIR reports it appearing in about 39% of breaches across the broader attack chain.
  • Phishing was IBM’s most frequent initial attack vector in its 2025 cost report, at 16% of studied breaches.
  • Third-party involvement increased by 60% from Verizon’s previous dataset, reaching 48% of total breaches.

Metric

Share

Source/method

Human element present

62%

Verizon DBIR, all breaches

Vulnerability exploitation

31%

Verizon DBIR, initial access vector

Credential abuse

13% initial / ~39% broader chain

Verizon DBIR, different denominators

Phishing

16%

IBM, initial attack vector

Third-party involvement

48%

Verizon DBIR, total breaches

The pattern is consistent: the highest-value controls are still basic but difficult operational work, including timely patching, phishing-resistant authentication, credential protection, supplier oversight and employee training.



How much does a data breach cost on average?

  • The global average breach cost is $4.44 million in 2025, per IBM.
  • That is down 9% from $4.88 million, the first decline in five years.
  • In the US, the average hit a record $10.22 million.
  • Healthcare is the costliest industry at $7.42 million, according to IBM’s 2025 report.
  • The average breach takes 241 days to identify and contain.

Metric

Figure

Global average

$4.44 million

US average

$10.22 million

Breach lifecycle

241 days

The global dip is real but misleading on its own, driven by faster detection and containment at mature organizations. For US businesses, costs are rising the other way, pushed up by higher regulatory fines and detection and escalation costs, making the country the most expensive place to suffer a breach.



Which CMS platforms see the most website infections?

Note: these figures come from security-firm cleanup and scan data and reflect market share as much as risk.

  • WordPress made up 95.5% of detected CMS infections in Sucuri’s dataset.
  • That reflects WordPress’s large footprint; W3Techs reports it on about 42% of all websites and roughly 59% of sites with a known CMS.
  • Patchstack’s 2026 report found 91% of new WordPress vulnerabilities in plugins and 9% in themes, with only 6 low-priority core vulnerabilities.
  • Outdated extensions are a major website security risk because attackers can scan for and exploit known plugin, theme and third-party component weaknesses.
  • Any platform’s risk rises sharply with neglected updates.

Factor

Detail

Most-seen CMS in Sucuri’s infection data

WordPress (95.5%)

WordPress usage share (W3Techs)

~42% of all sites, ~59% of known-CMS sites

New WordPress vulnerabilities by component (Patchstack 2026)

91% plugins, 9% themes, 6 core

WordPress tops Sucuri’s cleanup data because it has a very large web footprint, not because that data proves it is uniquely insecure. The real lesson is in the extension data: most newly reported WordPress vulnerabilities were in plugins or themes, while Patchstack found only a few low-priority core issues. See our WordPress market share research.



How many sites are flagged by Google Safe Browsing for malware?

  • Google Safe Browsing protects over 5 billion devices every day.
  • It scans billions of URLs daily to find unsafe sites.
  • It discovers thousands of newly unsafe sites each day.
  • Many flagged sites are legitimate ones that attackers compromised.
  • Safe Browsing covers phishing, social engineering, malware and unwanted software as distinct threat categories.

Metric

Figure

Devices protected

5 billion+

URLs scanned daily

Billions

New unsafe sites found daily

Thousands

Safe Browsing is the web’s quiet immune system. It not only warns visitors but also alerts site owners when their sites are compromised, which is often how a small business first learns it has been hacked. To secure your site, see our HTTPS and SSL research.



Sources & additional resources

Web Hosting Services helps you keep your site secure, with independent security and hosting research, current hosting deals from providers with built-in security, and managed WordPress hosting with automatic updates, firewalls and malware scanning.

Disclaimer: This article is for informational purposes only and is not legal, technical, cybersecurity, financial, insurance, business, hosting or purchasing advice. Website hacking statistics, breach-cost estimates, malware infection rates, vulnerability data, CMS infection shares, Safe Browsing figures, phishing and credential-abuse trends, third-party breach involvement, remediation datasets, scan-based measurements and security-report methodologies can change at any time and may vary by source, reporting period, website sample, platform, industry, geography, attacker behavior, detection method and incident definition. Always confirm current figures, security risks, compliance obligations, hosting requirements, remediation steps, insurance coverage and methodology directly with the cited source, security provider, hosting provider, legal advisor, insurer, cybersecurity professional or qualified expert before making website security, hosting, business, insurance or purchasing decisions based on website hacking statistics.

Website hacking statistics infographic showing a $4.44 million global and $10.22 million US average breach cost on a shared dollar axis, four separate denominator bands for breach causes with credential abuse appearing at both 13% and ~39%, a 1.66% infection rate drawn as a sliver of 70.8 million scans, and WordPress at 95.5% of infections against 59% of known-CMS sites and 42% of all websites on three separate tracks.
Breaches are expensive and ordinary, and almost every website hacking statistic changes its meaning depending on what it is a percentage of.